Skip to content
CyberSmithSECURE
Under Attack

Incident Response & Ransomware Recovery

Digital Forensics and Investigation

Forensics answers questions that carry consequences: what did this person take, how long was the attacker inside, was personal data accessed. Because those answers get used in disciplinary hearings, regulatory filings and courtrooms, how the evidence was acquired matters as much as what it shows. Every step is documented, hashed and defensible.

Methodology

  1. 01

    Scoping and legal context

    What question the investigation must answer, who commissioned it, and whether findings may be used in disciplinary, regulatory or legal proceedings — which determines the evidential standard from the first action.

  2. 02

    Evidence identification and preservation

    Systems, accounts, cloud tenants and devices in scope, with preservation notices and litigation holds applied before anything can be overwritten.

  3. 03

    Forensic acquisition

    Write-blocked disk imaging, memory capture and cloud log export, each hashed at acquisition and verified, with chain of custody documented from that moment.

  4. 04

    Timeline construction

    File system, registry, event log, browser and application artefacts correlated into a single timeline across all sources.

  5. 05

    Artefact analysis

    Execution evidence, file access, USB device history, cloud sync, email activity and deleted file recovery, according to the question being answered.

  6. 06

    Data movement analysis

    What was copied, to where, and when — removable media, cloud storage, personal email and messaging platforms.

  7. 07

    Attribution and corroboration

    Findings corroborated across independent artefact sources, because a single artefact is rarely sufficient to support a conclusion someone will contest.

  8. 08

    Reporting and testimony

    A report written to be understood by a non-technical reader and to withstand challenge, with expert testimony available where proceedings require it.

Approach to testing

  • Evidential standard from the first action, because it cannot be applied retrospectively. If there is any possibility of proceedings, acquisition is done properly the first time.
  • Findings are corroborated across independent artefacts. A single registry key is an indication; three independent artefacts agreeing is a finding.
  • Confidence is stated explicitly. 'The file was copied to a USB device' and 'a USB device was connected and the file was accessed in the same period' are different claims, and the report distinguishes them.
  • Absence of evidence is reported as such. Logs that were not retained, or artefacts overwritten before preservation, are stated plainly rather than papered over with inference.
  • The investigator is independent of the outcome. CSS reports what the evidence shows, including where it does not support the commissioning party's expectation.

Types of assessment

Incident forensics (default)

Establishing how an intrusion occurred, its extent and what was accessed. Usually follows or accompanies incident response.

Insider investigation

Data theft, policy violation or misconduct by an employee. Requires particular care over scope, privacy and employment law.

Data breach scope determination

Establishing exactly what personal data was accessed, to support a notification decision that regulators will scrutinise.

Litigation support and eDiscovery

Evidence preservation, collection and analysis for civil proceedings, with expert testimony where required.

Frameworks and standards

ISO/IEC 27037
Identification, collection, acquisition and preservation of digital evidence — the acquisition standard followed.
ISO/IEC 27041 / 27042
Assurance of investigation methods, and analysis and interpretation of evidence.
NIST SP 800-86
Integrating forensic techniques into incident response.
ACPO / equivalent good practice guides
Principles for handling digital evidence, particularly around preserving original media.
Indian Evidence Act and IT Act provisions
Where findings may be used in Indian legal proceedings, including Section 65B certification requirements.

Tools used

Tooling is where testing starts, not where it ends. Every automated result is reproduced by hand before it reaches a report.

FTK Imager / dd with write blockers

Forensically sound acquisition with hash verification at capture.

Autopsy / X-Ways

File system analysis, deleted file recovery and artefact extraction.

Volatility

Memory analysis for process, network and injected code evidence.

Plaso / Timesketch

Super-timeline construction across all artefact sources.

KAPE

Targeted artefact collection where full imaging is impractical.

Cloud audit log tooling

Microsoft 365, Google Workspace and cloud provider log acquisition and analysis.

Hashing and chain of custody tooling

Documented custody records from acquisition to reporting.

Checklist approach

The checklist is the floor, not the ceiling. It guarantees coverage so nothing standard is missed; the findings that matter usually come from what a tester does after it is complete.

Acquisition

  • Write-blocked or verified read-only acquisition
  • Hash calculated at acquisition and verified after transfer
  • Memory captured before power-down where the system is live
  • Cloud logs exported within their retention window
  • Chain of custody documented from first contact
  • Preservation notice issued to prevent overwriting

System artefacts

  • Program execution: prefetch, shimcache, amcache, userassist
  • File access and Most Recently Used artefacts
  • Event logs including deletion and clearing events
  • Registry hives and their transaction logs
  • Scheduled tasks, services and persistence
  • Volume shadow copies and their contents

Data movement

  • USB and removable media connection history
  • Files copied to removable media
  • Cloud sync client activity and uploaded content
  • Personal webmail and messaging platform usage
  • Print history
  • Archive creation preceding transfer

Account and access

  • Authentication history across systems and cloud
  • Privilege changes and group membership modifications
  • Remote access sessions and their source
  • Mailbox rules, delegation and forwarding
  • OAuth grants and application access

Evidential integrity

  • Every finding corroborated across independent artefacts
  • Confidence stated per finding
  • Gaps in evidence documented explicitly
  • Analysis reproducible from the preserved images
  • Section 65B or equivalent certification where required

How findings are scored

Every finding is scored on CVSS 3.1 and placed in one of five levels. The executive summary adds a sixth band — Compliant — so components that passed appear on the same chart as those that did not.

Critical
Immediate measures must be taken. These vulnerabilities can allow an attacker to take complete control of the application or server — stealing user data, tricking users into supplying sensitive information, or defacing the site.
High
Maximum risk associated with a specific vulnerability instance. May enable an attacker to compromise the application and its data, partially or completely, or to modify application behaviour beyond its intended purpose. To be handled with utmost priority.
Medium
Considerable risk. May enable an attacker to exploit the application to a particular level, gaining low-level information that can be used to craft more specific attacks.
Low
Lowest risk. May allow an attacker to gain some information about the application that was not intended to be known, without an exploitation technique currently available at that instance.
Informational
A functionality or component is missing best-practice implementation. Not a risk today, but may become one as the application changes or as exploitation techniques, policy or legal requirements evolve.

Scan types selected

  • Safe Checks
  • Standard / OWASP Top 10
  • Destructive
  • SANS Top 25
  • Business Logic Vulnerability Testing

Standard toolset by stage

OSINT
Datasploit, Google Dorks, Shodan
Enumeration & Scanning
Nmap, Wfuzz, Unicornscan
Domain Enumeration
Nikto, DnsRecon, Knock
Crawling & Fuzzing
Burp Suite, Acunetix, Netsparker
Vulnerability Analysis
OpenSSL, sqlmap, CVE-Details
Exploitation
Metasploit, Netcat, Exploit-DB

How CSS tests

A unified swarm of agents, for blind spot detection

AI agents drive several testing tracks against the same target at once, then cross-check each other. A single tester works one hypothesis at a time; parallel agents cover the space a sequential pass leaves behind.

  • Super-timeline construction across multiple images and log sources produces millions of events; surfacing the relevant hundred is exactly what parallel analysis is for.

  • Cross-artefact corroboration — confirming a single conclusion against execution, file access and USB artefacts independently — is systematic checking that manual analysis performs only for the findings an investigator already suspects.

  • Keyword and pattern search across terabytes of unallocated space is breadth work.

  • Anomaly detection across authentication logs spanning months identifies the session that matters among hundreds of thousands of normal ones.

Analysis is assisted; conclusions are not. Every finding in a forensic report is reached and asserted by a human investigator who can defend it under challenge. Agents surface candidates and correlate artefacts; an agent's output never appears in a report as a finding, because an expert witness must be able to explain how a conclusion was reached.

Why this differs

What CSS does that most vendors do not

Every one of these is checkable. Ask any vendor for the same and compare the answers.

Evidential standard from the first action

Acquisition is done to a standard that survives challenge whether or not proceedings are anticipated, because that decision cannot be revisited after the fact.

Confidence stated, gaps declared

Findings carry an explicit confidence level, and missing evidence is reported as missing rather than filled with inference. That is what makes the rest of the report credible.

Independent of the outcome

CSS reports what the evidence shows, including where it does not support the commissioning party's expectation. An investigator who finds what the client hoped for is not much use in a hearing.

Written to be understood

The report is written for a non-technical reader — an HR panel, a regulator, a judge — while remaining technically defensible. Most forensic reports fail one of those two tests.

Reporting

Two documents, two audiences

Both are produced for every engagement. They are not the same document at two lengths — they answer different questions and are written separately. The structure below is the one CSS actually issues.

Technical assessment report

For the engineers who will fix it

  • Disclaimer, and Limitations on Disclosure and Use
  • Risk Level & Description — the five levels above, scored on CVSS 3.1
  • Scan Type — which of the five assessment types were selected
  • Assessment Scope — the control areas covered
  • Assessment Date — the exact testing window
  • Objective of the Assessment — objectives listed against completion status
  • Tools Utilization — manual and automated tooling by stage
  • Summary of the Assessment
  • Overall Recommendations, split into Must Have and Should Have
  • Vulnerability Overall Classifications as per Organization
  • Security Issues Highlighted
  • The Key Findings — each with evidence and detailed recommendation
  • Summary of Findings & Conclusion

For this assessment specifically

  • Scope, commissioning party, questions posed and the evidential standard applied
  • Evidence inventory with acquisition method, hashes and chain of custody
  • Methodology, with tooling and versions, so analysis is reproducible
  • Timeline of relevant events with source artefact for each
  • Findings with confidence level and corroborating artefacts named
  • Data movement analysis: what, where and when
  • Explicit statement of evidence gaps and their cause
  • Section 65B or equivalent certification where required

Executive summary

For the people who will fund the fix

  • Objectives, each against a completion status
  • Overall Finding of the Assessment — total threats identified, broken down by component and severity
  • Summary of the Assessment
  • Artefacts of the Assessment — the key findings as a numbered register with severity
  • Observation of the Assessment — the major attacks the organisation should be prepared for, given what was found
  • Overall Recommendation, including a Business Enabling Recommendation sequence
  • Must Have and Should Have actions

For this assessment specifically

  • The question asked, and the answer, in plain language
  • What the evidence supports, and how confidently
  • What could not be determined, and why
  • Timeline in dates rather than timestamps
  • Implications for notification, disciplinary or legal action
  • One page

Case studies

What this finds in practice

Representative engagement patterns. Sector and scale only — no client is named, and no detail is included that could identify one.

A professional services firm investigating a departing partner suspected of taking client data.

Finding
USB artefacts showed a device connected three times in the final fortnight. File access artefacts showed 2,100 client documents opened in a pattern inconsistent with normal work, and a personal cloud sync client had been installed eleven days before resignation and removed two days before departure — with its installation and uninstallation both recoverable.
Recommendation
Findings supported the firm's position in proceedings. Separately, the absence of DLP and removable media control was reported as the reason the activity was possible.
Outcome
The matter was settled on the strength of the corroborated timeline. The firm implemented removable media control and cloud sync restrictions the following quarter.

A financial services firm determining breach scope after an intrusion.

Finding
The attacker had accessed a file server for six days. Analysis of access artefacts and server logs established exactly which directories were opened and which were not, narrowing the affected population from an assumed 40,000 records to a documented 1,340.
Recommendation
Notify on the basis of the documented scope, with the evidence retained to support the figure if the regulator queried it.
Outcome
Notification proceeded on the narrower scope. The client's counsel regarded the documented basis as the most valuable output, since an unevidenced estimate would have had to assume the larger figure.

A manufacturer investigating suspected fraud in procurement.

Finding
Email and file artefacts showed the suspected activity, but the critical fortnight fell outside the mailbox audit retention window, which had been set to 90 days. That evidence was unrecoverable.
Recommendation
Report the gap plainly rather than inferring across it, and extend audit log retention to twelve months so a future investigation is not defeated by retention settings.
Outcome
The investigation reached a partial conclusion, stated as such. Retention was extended across the tenant, which the client described as the finding with the most lasting value.

Next

Scope this assessment

Most scopes are settled in one call. Tell us what the application does and who uses it, and we will tell you what testing it properly involves.